Glossary

Every payments term, in plain English.

193 terms from chapter 3 of the Payments Playbook, free and complete. Written the way you would explain them to a colleague, not the way a scheme rulebook does.

The Basics (Start Here)

Payment Intent
Fancy way of saying "I want to charge this customer for something." It tracks the whole process from start to finish.
Payment Method
How people pay you - credit card, bank transfer, PayPal, crypto, whatever.
One-time Payment
Charge someone once and you're done. Like buying a coffee.
Subscription
Charge someone repeatedly until they cancel. Like Netflix.
Authorization
Checking if someone has money without taking it yet. Like putting a hold on a hotel room.
Capture
Actually taking the money after authorization. You have to do this pretty quickly or the hold expires.
Auth-Only
Authorization without automatic capture. Used when you need to verify funds before fulfilling an order.
Settlement
The process of money actually moving from their bank to yours. Takes a few days because banks move slow.
Payout
When you finally get your money in your own bank account. The good part.
Pre-authorization
Temporarily holding funds without capturing them. Like putting a hold on a gas pump before you fill up.
Void
Cancelling a transaction before it settles. Like hitting "undo" but for payments.
Partial Capture
Taking only part of an authorized amount. Like ordering $100 worth of stuff but only $50 is in stock.
Multi-capture
Capturing an authorization in multiple parts over time. Useful for partial shipments or installments.
Incremental Authorization
Increasing an existing authorization amount. Used by hotels and gas stations when the final amount exceeds the initial hold.
Batch Processing
Processing multiple transactions together at set times. Cheaper but slower than real-time.
Real-time Processing
Processing transactions immediately as they occur. More expensive but customers expect it.
Payment Descriptor
What appears on the customer's credit card statement. Getting this right reduces chargebacks from confused customers.

The Players in the Game

Payment Processor
The company that actually handles moving money around. Like Stripe or Square.
Gateway
The thing that securely captures card info from your website and sends it to the processor.
Merchant Account
A special business bank account for accepting payments. Some processors include this, others make you get your own.
Merchant of Record (MoR)
The business legally responsible for the sale. If you use Paddle, they're the MoR and handle all the tax headaches for you.
Payment Facilitator (PayFac)
Business model that lets you onboard sub-merchants under your account. Think Shopify Payments or Square.
Acquiring Bank
Your bank in the payment process - they work with your processor to get you paid.
Issuing Bank
The customer's bank - the one that issued their credit card.
Card Networks
Visa, Mastercard, Amex, Discover, UnionPay, JCB - the companies that connect all the banks together.
Interchange Fee
The fee banks charge each other for processing cards. You end up paying it through your processor fees.
Assessment Fee
What card networks (Visa/MC) charge for using their network. Usually around 0.14% on top of interchange.
Processor Markup
Your payment company's profit - what they charge on top of interchange and assessment fees.
PSP
Payment Service Provider - companies like Stripe that bundle everything together so you don't need separate merchant accounts.
MCC (Merchant Category Code)
Four-digit code classifying your business type. Affects which cards you can accept and what fees you pay.

When Things Happen

Refund
Giving someone their money back. Usually because they asked nicely, sometimes because they demanded it.
Chargeback
When a customer disputes a charge through their bank instead of contacting you first. Expensive and annoying.
Friendly Fraud
When legitimate customers file chargebacks claiming fraud on purchases they actually made. Growing problem.
Retrieval Request
When a customer asks their bank for transaction details. Often a precursor to a chargeback - your chance to provide documentation.
Decline Code
The reason the bank said "no" to a payment. Could be anything from "no money" to "suspicious activity."
Webhook
How payment companies tell your app when something happens. Like a text message saying "hey, you got paid!"
Webhook Signature
Proof that the webhook actually came from who it says it did. Without it, you're trusting whoever sent the request.
Idempotency
Fancy word for "don't charge someone twice if they click the button twice." They will click it twice.
Tokenization
Turning credit card numbers into random tokens so you don't have to store the real numbers. Much safer, and often required for PCI compliance.
Network Tokenization
Card networks (Visa, Mastercard) providing tokens that update automatically when cards are reissued. Better than merchant tokenization.
Card-on-File
Storing a customer's payment method for future purchases. Requires their consent and secure tokenization.

Subscription Stuff

Proration
Math to figure out partial charges when someone upgrades mid-month. Like paying extra for premium Netflix halfway through the month.
Dunning
Politely (then not so politely) asking customers to fix their expired credit cards so you can keep charging them.
Billing Engine
The system that handles all your subscription logic - when to charge, how much, what happens when cards fail.
Trial Period
Free time before you start charging. Great for customers, nerve-wracking for you.
Grace Period
Extra time after a payment fails before you cut someone off. Being nice pays off sometimes.
Churn
How fast people cancel. Lower is better. This number will keep you up at night.
MRR
Monthly Recurring Revenue - the money you can count on each month. The holy grail of SaaS metrics.
ARR
Annual Recurring Revenue - MRR times 12. The number investors want to see.
LTV
Lifetime Value - how much money you'll make from a customer before they leave you. Higher is better.
CAC
Customer Acquisition Cost - how much you spend to get each new customer. LTV should be much higher than this.
NRR
Net Revenue Retention - revenue from existing customers including upsells minus churn. Over 100% means you're growing without new customers.
Freemium
Free basic service with paid premium features. Great for customer acquisition, challenging for conversion.
Usage-based Billing
Charging based on actual consumption or usage. Like your electricity bill but for software.
Tiered Pricing
Different price levels with different features. Bronze, Silver, Gold - you know the drill.
Per-seat Pricing
Charging per user account. Simple to understand, scales with team growth.
PCI DSS
Payment Card Industry Data Security Standard - security rules for handling credit card data. Current version is v4.0.1; v3.2.1 retired March 2024. Break these and you're in big trouble. Most payment processors handle this for you.
SAQ
Self-Assessment Questionnaire - the PCI DSS compliance form you fill out based on how cards touch your systems. Types A, A-EP, B, B-IP, C, C-VT, D - lower-letter SAQs cover less surface area.
3D Secure (3DS)
Extra security step that makes customers prove they own their card. Reduces fraud but some customers abandon checkout.
EMV 3DS / 3DS 2.x
Modern 3DS (formerly "3D Secure 2.0") - frictionless authentication driven by 100+ data points, with a challenge fallback only when needed. Versions 2.2 and 2.3 are current; 1.0 is deprecated.
Strong Customer Authentication (SCA)
EU rule requiring extra verification for payments. Mandatory in the EEA under PSD2 with documented exemptions.
SCA Exemptions
Ways to skip SCA for low-risk transactions: low-value (under 30 EUR), MIT (merchant-initiated), TRA (transaction risk analysis), trusted beneficiary, recurring fixed amount, corporate B2B.
PSD2
Payment Services Directive 2 - EU regulation that mandates SCA and enables Open Banking. Why European payments got more complex.
PSD3 / PSR
Successor package to PSD2: Payment Services Directive 3 plus the Payment Services Regulation. Proposed by the European Commission in June 2023; expected to enter force late 2026 / 2027. Tightens fraud liability, refines SCA, and lifts most rules to a directly-applicable regulation.
CVV / CVC / CID
Card Verification Value (Visa) / Code (Mastercard) / Card Identification (Amex) - the 3- or 4-digit code on the card. Storing it after authorization is a PCI violation; merchants must drop it.
AVS
Address Verification Service - the issuer checks the billing address you submit against the one on file and returns a match code. Required for CNP fraud controls; not foolproof.
BIN
Bank Identification Number - the first 6 (or 8 in some schemes) digits of a card number that identify the issuer, card brand, country, and product. Used for routing, fraud rules, and BIN-based fees.
PAN
Primary Account Number - the long number on the front of the card. The number PCI scope and tokenization are organized around.
EMV
Europay/Mastercard/Visa - the global chip-card standard. EMV Contact (chip-and-PIN), EMV Contactless (tap-to-pay), and EMV 3DS (the 3DS 2.x family) all sit under the same standards body.
CNP
Card Not Present - any transaction where the card isn't physically dipped, tapped, or swiped. Higher interchange, higher fraud risk, where 3DS and AVS earn their keep.
Reason Code
The numeric code an issuer assigns to a chargeback explaining why the customer disputed (e.g., "fraud", "product not received", "credit not processed"). Each card network has its own codebook.
Dispute
Umbrella term for a customer challenging a charge. A dispute may resolve at the retrieval-request stage with documentation, or escalate into a chargeback.
ISO 20022
The global financial-messaging standard replacing legacy formats (SWIFT MT, ISO 8583 for cards). SWIFT MT/MX coexistence ended November 2025; SEPA, Fedwire, CHAPS, and most cross-border rails now run on pacs.* messages.
VAT
Value-Added Tax - consumption tax used in Europe and many countries globally. Changes based on where your customer lives, not where you are.
GDPR
EU privacy rules that basically say "don't be creepy with customer data." Applies globally if you have EU customers.
KYC
Know Your Customer - proving your customers are who they say they are. Mainly for financial services.
AML
Anti-Money Laundering - making sure you're not helping criminals wash their money. Also mainly financial services.
Sanctions Screening
Checking customers against government restricted lists. Required to avoid doing business with bad actors.
PEP
Politically Exposed Person - extra scrutiny for government officials and their families due to corruption and bribery risks.
Transaction Monitoring
Automated surveillance for suspicious activity patterns. Required for AML compliance.
SAR
Suspicious Activity Report - filed with authorities when something looks fishy. Nobody wants to file these.

Marketplace Madness

Split Payment
Taking one payment and dividing it between multiple people. Like splitting a restaurant bill, but automated.
Escrow
Holding money in the middle until everyone's happy. Like having a referee hold the money until the work is done.
Marketplace
Platform where lots of people buy and sell stuff. Think eBay, Etsy, or Uber.
Platform Fee
Your cut of every transaction. How marketplaces make money.
Connected Account
Individual seller accounts linked to your platform. Lets you pay them directly.
Payout Schedule
When sellers get paid. Daily, weekly, monthly - depends on your rules and their patience.

Integration Methods

SDK
Software Development Kit - pre-built code libraries for integrating payments. Saves you from starting from scratch.
API
Application Programming Interface - how your code talks to payment providers. REST APIs are most common.
Redirect Flow
Sending customers to another site to complete payment. They leave your site temporarily but come back.
Embedded Checkout
Payment form that stays on your site throughout the process. Better user experience but more PCI considerations.
Hosted Payment Page
Payment processor's secure checkout page. They handle security, you handle everything else.
Sandbox/Test Mode
Safe environment for testing integrations without real money. Always develop here first.
Webhook Endpoint
URL on your server that receives payment notifications. It has to be up when the provider calls, and it has to check the signature.
Callback URL
Where payment providers send customers after completing external payment flows.

Other Ways People Pay

BNPL
Buy Now, Pay Later - layaway in reverse: the customer gets the goods now and pays in installments. Klarna, Afterpay, etc. Popular with people who don't want to pay right now.
Digital Wallet
Apple Pay, Google Pay, PayPal - storing payment info on your phone or computer for quick checkout.
NFC
Near Field Communication - the technology behind tap-to-pay. Your card or phone talks to the reader wirelessly.
Contactless Payments
Tap-to-pay using NFC technology. Wave your card or phone near the reader and you're done.
QR Code Payments
Scanning codes to initiate payments. Dominant in Asia, spreading everywhere else.
In-app Billing
Payments processed through mobile app stores. Apple takes 15-30%, Google similar - depends on your revenue and business type.
ACH
Automated Clearing House - bank-to-bank transfers in the US. Cheaper than cards but slower. Great for big payments.
SEPA
Single Euro Payments Area - European bank transfer system. Like ACH but for euros across 41 countries (27 EU members plus the EEA, UK, Switzerland, Monaco, San Marino, Vatican, Andorra, and several Balkan accession states).
SEPA Instant
Real-time SEPA transfers that complete in seconds. Not all banks support it yet.
SWIFT
Society for Worldwide Interbank Financial Telecommunication - the global network for cross-border wire transfers. Expensive but works everywhere.
RTP
Real-Time Payments - instant bank transfers in the US. Like ACH but immediate.
FedNow
The Federal Reserve's instant payment system. Competitor to RTP, launched 2023.
Open Banking
Letting apps access your bank account directly (with permission). Enables account-to-account payments without cards.
Cryptocurrency
Digital money like Bitcoin. Useful for cross-border payments, but volatile and complex for most merchants.
Stablecoin
Crypto designed to maintain stable value, usually tied to the dollar. Less volatile than Bitcoin.
CBDC
Central Bank Digital Currency - government-issued digital money. China's digital yuan is the biggest example. Still emerging.

Regional Payment Methods

Alipay
China's dominant mobile payment platform with over 1 billion users. Essential for Chinese customers.
WeChat Pay
Payment system built into China's WeChat super-app. As important as Alipay in China.
UPI
Unified Payments Interface - India's instant payment system. Processes billions of transactions monthly.
PIX
Brazil's instant payment system. Free, fast, and wildly popular since launching in 2020.
M-Pesa
Mobile money service dominant in Kenya and parts of Africa. Works without smartphones or bank accounts.
iDEAL
Netherlands' most popular online payment method. Bank transfer that's instant and trusted.
Bancontact
Belgium's national payment scheme. Required if you're selling to Belgians.
Giropay
German online bank transfer method, wound down in 2024: most processors (Stripe included) stopped accepting it on 30 June 2024 and the scheme shut for good on 31 December 2024. Merchants moved to Klarna Pay Now (formerly Sofort), SEPA-based open banking flows, or Wero, the EPI successor. Still shows up in older docs; don't build a new integration on it.
Boleto
Brazilian payment voucher. Customer gets a barcode to pay at banks or shops. Still popular despite PIX.
OXXO
Mexican convenience store payment. Customers pay cash at 20,000+ stores. Essential for unbanked customers.
Faster Payments
UK's real-time bank transfer system. Most UK bank transfers complete in seconds.
Interac
Canada's national debit network. Interac e-Transfer is how Canadians send money to each other.

International Payment Terms

Cross-Border Payments
Payments between different countries. Always more complicated and expensive than domestic.
Currency Conversion
Changing dollars to euros (or whatever). Someone always charges a fee for this.
FX Margin
The extra percentage charged on top of the real exchange rate. Typically 2-4% with traditional banks, 0.5-1% with modern fintech providers.
Multi-Currency Pricing
Showing prices in the customer's local currency. Increases conversion but adds complexity.
Dynamic Currency Conversion
Letting customers pay in their home currency at point of sale. Convenient but usually expensive for them.
Correspondent Banking
How smaller banks connect to the global payment system through bigger banks. Like using a middleman.
IBAN
International Bank Account Number - up to 34 characters identifying bank accounts, primarily used in Europe.
BIC/SWIFT Code
Bank Identifier Code - 8-11 characters identifying specific banks for international transfers. Same thing as SWIFT code.
Settlement Windows
Specific times when international payments actually get processed. Miss the window, wait until tomorrow.
Cross-Border Fee
Additional charge for processing cards issued in different countries. Usually 1-2% on top of regular fees.

Security Architecture

DevSecOps
Development, Security, and Operations combined - building security into everything from the start instead of adding it later.
Zero Trust Architecture
"Trust no one, verify everything" - even if someone's inside your network, they still have to prove who they are.
SIEM
Security Information and Event Management - system that watches all your logs and tries to spot bad guys. Like having a very paranoid security guard.
SOC
Security Operations Center - team (or room full of people) watching monitors 24/7 looking for security incidents.
SOAR
Security Orchestration, Automation and Response - automating security responses so you don't need humans to click buttons when bad things happen.
WAF
Web Application Firewall - filters out malicious web traffic before it reaches your app. Like spam filtering for hackers.
API Gateway
The bouncer for your APIs - controls who gets in, how many requests they can make, and kicks out troublemakers.
Rate Limiting
Stopping people from hammering your API with too many requests. Like "you can only try 100 times per minute."

When Security Goes Wrong

Threat Modeling
Thinking like a hacker to figure out how someone might break your stuff before they actually do it.
MTTD
Mean Time to Detect - how long it takes to notice someone's hacking you. Shorter is better.
MTTR
Mean Time to Respond - how long it takes to fix things after you notice the hack. Also shorter is better.
Incident Response
Your plan for when everything goes wrong. Like a fire drill but for cyber attacks.
Forensic Analysis
Figuring out exactly what the hackers did, after the fact, so you can prevent it next time.
Security Posture
How secure you actually are vs. how secure you think you are. Usually there's a gap.
Account Takeover (ATO)
When fraudsters gain access to legitimate customer accounts. Growing problem with credential stuffing attacks.

Protecting Data

Encryption at Rest
Scrambling data when it's stored so even if someone steals your hard drives, they can't read anything.
Encryption in Transit
Scrambling data while it's moving between servers. Like HTTPS but for everything.
Data Masking
Hiding sensitive parts of data for testing. Like showing "**--**-1234" instead of the full card number.
Key Management
Keeping track of all your encryption keys securely. Lose these and you're in serious trouble.
PCI Scope
Which parts of your system handle card data and must meet PCI DSS requirements. Smaller scope = easier compliance.

Managing Security (The Hard Part)

Vulnerability Management
Finding security holes in your stuff before bad guys do. It's like whack-a-mole but with more anxiety.
Security Orchestration
Making all your security tools work together instead of against each other. Harder than it sounds.
Behavioral Analysis
Watching how users and systems normally behave so you can spot when something's weird.
Supply Chain Security
Making sure the code libraries you use aren't secretly malicious. Turns out this is a big problem.
Compliance Automation
Using tools to check if you're following all the rules so humans don't have to do boring compliance work.
Security Metrics/KPIs
Numbers that tell you if your security is actually working or just expensive theater.
Threat Intelligence
Information about current and emerging security threats. Like weather reports but for hackers.
Penetration Testing
Hiring ethical hackers to break into your stuff so you can fix it before the bad guys find it.
Security Auditing
Formal review of your security controls. Usually required for compliance and always expensive.

Stopping the Bad Guys

Machine Learning Fraud Detection
Teaching computers to spot fraud patterns that humans might miss. Gets smarter over time.
Risk Scoring
Giving each transaction a "sketchy score" from 1 to 100. High scores get extra scrutiny.
Velocity Checking
Flagging when someone tries to make way too many transactions way too fast. Usually a red flag.
Device Fingerprinting
Creating a unique ID for each device based on its characteristics. Hard to fake.
Geofencing
Blocking transactions from certain countries or locations. Blunt but effective.
Blocklist/Allowlist
Bad list and good list. Bad actors get blocked, trusted customers get fast lanes.
False Positive
When your fraud detection flags a good customer as suspicious. Annoying for everyone involved.
False Negative
When fraud slips through your detection. Expensive lesson in why security is hard.
Fraud Rules Engine
System that runs your fraud detection rules automatically. Can get complex fast.
Manual Review
Having humans look at suspicious transactions. Slow but sometimes necessary.
Biometric Authentication
Using fingerprints, face recognition, or other biological identifiers to verify identity.
Step-up Authentication
Requiring additional verification only for risky transactions. Balances security with user experience.

Money Stuff

Cash Flow
Money coming in vs. money going out. Hopefully more in than out.
Float
The annoying time between "customer paid" and "money in your account." Usually a few days.
Reserve
Money your payment processor holds in case of chargebacks. Gets released eventually.
Rolling Reserve
A percentage of your revenue that gets held for a set period. Like a security deposit.
Minimum Payout
How much money you need to accumulate before they'll actually pay you. Usually $25-100.
Forex
Foreign exchange rates - how much a euro is worth in dollars today. Changes constantly and affects international sales.
Effective Rate
Your actual payment processing cost as a percentage. What you really pay after all fees are included.
Blended Rate
One simple rate that covers all your different card types. Easier to understand but usually more expensive.
Interchange Plus
Pricing where you pay the actual interchange rate plus a small markup. More transparent and usually cheaper at volume.
Volume Tiers
Discounts you get for processing more money. Like buying in bulk but for payments.
Card Mix
The percentage breakdown of what types of cards your customers use. Affects your overall costs significantly.
Acquiring Markup
The fee your acquirer charges on top of interchange. Their profit margin that gets added to your costs.
Network Fees
Additional fees charged by card networks beyond assessment fees. Because apparently assessment fees weren't enough.
Gateway Fees
Monthly or per-transaction fees for using a payment gateway. Usually small but adds up.
Chargeback Fee
The fee you pay every time someone disputes a charge, even if you win the dispute. Usually $15-25 per chargeback.
Net Settlement
Final amount after fees and adjustments are deducted. What actually hits your bank account.
Gross Settlement
Total amount before any deductions. The number that looks good in reports.
Working Capital
Short-term funds available for operations. Keeping the lights on while waiting for payments to settle.
Revenue Recognition
When you can count money as earned income. Accounting rules that make simple things complicated.

Where these come from

Chapter 3 of 42.

The glossary is the vocabulary. The other 41 chapters are what you do with it.

30-day money-back · Instant PDF and EPUB